Passwords in a Shared Spreadsheet: How to Fix It
7 min read
In most small companies the passwords do not live in a system. They live somewhere called "everybody knows". A shared spreadsheet, a note stuck to the side of a monitor, a message somebody posted in the group chat three years ago. That works, because the company is small, the people know each other, and the odds of anything going wrong look low. The catch is that the cost is not spread evenly across the years. It lands on one particular day: somebody leaves, an account gets logged into, or a customer asks who touched their record. This is about getting from where you are now to a state where you can answer that question.
1. Find out where the passwords actually are
Take stock before changing anything. In a small company the passwords are usually spread across four places, and all four tend to exist at once. A shared spreadsheet or note, generally on a cloud drive, readable by anyone with the link. The message history in a chat app, findable by scrolling up. One person's memory, which means the whole company stops when that person is on leave. And the browsers, one copy per machine, not necessarily holding the same thing.
Taking stock is simple: list the services the company actually uses. Domain registrar, hosting or cloud provider, company email, accounting and invoicing, online banking, social platforms, the website admin. Then against each one write two things. Who currently knows this password, and whether this password is used anywhere else.
That list answers half the question by itself. Most people get halfway down and find the same password appearing five times, one of those under the name of somebody who left last year. At that point the question stops being whether to adopt a tool and becomes a very specific three or four accounts.
2. The real risk is not being hacked, it is having no answer
Shared passwords carry three risks, none of which involves a hacker in a film. They show no symptoms day to day. They all surface at once, on one specific day.
The first is departures. The person leaves and the password stays. Even with complete trust in them, you cannot confirm whether they saved it on a personal device or forwarded it to somebody for convenience. A shared password only has to be missed in one place for that entrance to stay open.
The second is spread. One password used across five services means that when any one of those services is breached, the other four are effectively open. Nobody has to break anything. Attackers take the credentials leaked from one site and try them against others, automatically, at volume.
The third is that you cannot trace anything. If everyone uses one account, the log holds one name. A record was changed, an order was cancelled, a payment went to a different bank account. You know something happened and you cannot say who did it. That becomes painful the moment you have to explain it to a customer or file an insurance claim.
3. Which accounts have to be one person, one login
Not every account needs splitting. Split too finely and nobody follows the rule, which is its own kind of failure. Two tests decide it: how irreversible the actions this account can take are, and whether losing it drags other accounts down with it. Run those two tests and most companies land on something like the table below.
| Account | Shareable | Why |
|---|---|---|
| Company email | No | Every other service sends its password reset here, so losing it loses everything |
| Domain registrar and hosting panel | No | A transferred domain takes the site and the mail with it, and recovery runs into weeks |
| Online banking and payment back ends | No | Money moves, and you have to be able to say who moved it |
| Website admin and internal systems | One login each | These systems already support multiple accounts with different rights, so sharing is a choice |
| Social and advertising platforms | Grant access instead | You can usually add a colleague's own account rather than hand over the master password |
| Small subscription tools | It depends | If it is to save on seats, price what that account can reach first |
The last row deserves a sentence. Five people sharing one seat to avoid paying for five is a common decision and not automatically a wrong one. It just has to be made with knowledge of what that account can reach. Sharing a read-only reporting login carries limited risk. Sharing a login that can export the entire customer list puts the saving and the possible loss in completely different orders of magnitude.
4. What to do about shared accounts you cannot split
Some accounts are singular by nature. The company's registered banking login, the business account with the telecoms provider, an older system that only ever issues one administrator. The answer there is not to force a split. It is to make the account controllable.
First, move it into a shared vault in a password manager rather than a spreadsheet. The difference is that you can say who has access, withdraw that access at any time, and have the contents actually disappear for that person afterwards. A spreadsheet cannot do this, because a copy was taken long before you withdrew anything.
Second, record who was granted access and when. This does not need to be elaborate; a single table is enough. Its real purpose shows up on the day somebody leaves, when it tells you exactly what to change instead of leaving you to guess from memory.
Third, set a trigger for rotating these passwords rather than a calendar interval. Rotate when somebody leaves, when a breach notification arrives, when an account starts behaving oddly. That is far more effective than changing everything every quarter, and colleagues do not experience it as busywork.
5. Browser-saved passwords against a password manager
This is the question that comes up most, and the answer is not that browsers are unsafe. Modern browsers store passwords encrypted and will warn you about weak or reused ones. That is considerably safer than a spreadsheet. If a spreadsheet is where you are today, letting the browser remember them is already progress.
The difference is that a browser vault is built for one person. It is tied to one individual's profile, and it has no concept of handing one password to a colleague and taking it back later. The only way to share is to read the credentials out loud, which puts you back where you started. It will also not tell you which entries to rotate when somebody leaves, and it keeps no record of who retrieved what and when.
Those are precisely the things a password manager adds: sharing, withdrawal, a record, and generating a random password nobody has to remember. For an individual those are conveniences. For a company they are the entire point. There are plenty of products and this does not recommend one, because what decides whether a tool works for you is the list below.
Five things to check before picking one
- Can it share a single credential rather than a whole account? This is the dividing line between personal and company use. Without it you are still passing a spreadsheet around.
- When access is withdrawn, does the other person really lose it? Ask whether the entry stops being displayed or the credential genuinely stops working. Rotating that password anyway is still the safer habit.
- Is there an access record? Who retrieved which entry and when. That is the only thing that lets you answer questions afterwards, and it is what makes a shared account tolerable at all.
- Can the master account itself take two-factor authentication? A password manager is where every password ends up, so its own door has to be the strongest one you have.
- Can you get your data out? An export in a standard format is what stops a tool locking you in, and it is what lets you keep an offline copy of your own.
6. The day somebody leaves
The thing most often missed in an offboarding process is not the door pass, it is the logins. And it is time-sensitive. Getting to it a few days after their last shift leaves a window, and that window is where the trouble happens.
Print the list below and run it every time somebody leaves. The order matters: cut off the entrance that can reset everything else first, then deal with the rest.
Run this in order, every time
- Disable the company mailbox, or at minimum change the password and sign out every device. Password resets for other services arrive here. Skip this and everything after it is wasted.
- Rotate every shared password they knew. The list from the first section is what tells you which ones. Without it this step becomes guesswork, and guesswork always misses something.
- Withdraw whatever was shared to them in the password manager. While you are there, check whether they had shared any of it onward to a third person.
- Check whether anything of the company's sits under their personal account. The domain registrar, admin rights on social platforms, and ownership of files on the cloud drive are the three that cause the most trouble.
- Move the second factor off their phone. They have left, and the codes their handset receives have left with them.
- Look at the sign-in logs again a week later. You are looking for a successful login from an unfamiliar location. Five minutes.
Password management sounds like adopting a system. The first step is only writing down where the passwords currently are. Most companies see the problem the moment that list exists, and find that only three or four accounts genuinely have to change. Start with email, the domain, and anything touching money: one login each, plus a second factor. The rest can follow at its own pace. The shared spreadsheet does not have to be deleted today. It just should not be the only thing you have.
Common questions
- Does a small company have to buy a password manager? Is the free tier enough?
- Not necessarily. With two or three staff and two or three shared accounts, listing them and moving email and the domain to one login each already gets you most of the benefit. When you do need a tool, free tiers usually cover one person well, but company use runs into sharing and withdrawing access, which is generally a paid feature. Judge on whether it can share a single credential, whether withdrawal really works, and whether there is an access record, rather than on price.
- Is sending a password over chat really that bad?
- The problem is not the moment of sending, it is that the message stays in the history forever. It travels with every phone, every computer that ever signed in, and every backup. If any one of those is lost or taken over, the password goes with it and you will not know. If you genuinely have to send one, rotate that password immediately afterwards, and do not put the username and the password in the same message.
- When an employee leaves, do all the passwords have to change?
- Not all of them, only the ones they knew, which is why the inventory from the first section matters. Without it you are left changing everything or guessing. Start by disabling the company mailbox, because every other service sends its reset there. Then rotate the shared passwords they knew, withdraw whatever was shared to them in the password manager, and move any second factor off their phone. Check the sign-in logs again a week later.